There are several ebooks that have been uploaded to libgen that contain PDF exploits, and from what I understand there's no way to remove them. The way that their library database works is by linking a book number to a file's md5 sum. On the filesystem they are stored something like `$drive:\$batch\$sum` where `$drive` is a Windows drive letter, `$batch` is the primary key of the document rounded to the nearest 1k, 1…
Or don't use a vulnerable PDF viewer, or OS.
Is Firefox lying to users about viruses in downloads?
51–60 of 76 posts
Re: Is Firefox lying to users about viruses in downloads?
#52If only the voting public understood about statistics, false positives, and false negatives. Even if Firefox did a full virus scan, there would still be false positives and false negatives in the results. The system designer always has to put their reporting threshold somewhere, and that always means making a decision to bias towards false positives or false negatives. Eliminating false positives means exploding the…
And why the hell should the browser act as an antivirus?. It's a browser, not an antivirus, it should assume the user knows what he's doing, not treat him like a toddler. It's just a huge annoyance with no considerable benefit.
Having said that, I do agree that browsers shouldn’t implement lots of crazy features but I personally don’t mind if they have some kind of malicious file scanning feature.
Re: Is Firefox lying to users about viruses in downloads?
#53There are several ebooks that have been uploaded to libgen that contain PDF exploits, and from what I understand there's no way to remove them. The way that their library database works is by linking a book number to a file's md5 sum. On the filesystem they are stored something like `$drive:\$batch\$sum` where `$drive` is a Windows drive letter, `$batch` is the primary key of the document rounded to the nearest 1k, 1…
I could be wrong but I think technically a PDF exploit only affects a single viewer program, like Acrobat on windows, right?
It's going to be rarer to find something of that scope, maybe even to the point of you being effectively right.
Re: Is Firefox lying to users about viruses in downloads?
#54Earlier quoted context omitted.
I could be wrong but I think technically a PDF exploit only affects a single viewer program, like Acrobat on windows, right?
It would depend on the exploit. For a simple example, an exploit that was a result of a flaw in the file specification could result in it being cross platform. It's going to be rarer to find something of that scope, maybe even to the point of you being effectively right.
Re: Is Firefox lying to users about viruses in downloads?
#55If only the voting public understood about statistics, false positives, and false negatives. Even if Firefox did a full virus scan, there would still be false positives and false negatives in the results. The system designer always has to put their reporting threshold somewhere, and that always means making a decision to bias towards false positives or false negatives. Eliminating false positives means exploding the…
And why the hell should the browser act as an antivirus?. It's a browser, not an antivirus, it should assume the user knows what he's doing, not treat him like a toddler. It's just a huge annoyance with no considerable benefit.
Re: Is Firefox lying to users about viruses in downloads?
#56There are several ebooks that have been uploaded to libgen that contain PDF exploits, and from what I understand there's no way to remove them. The way that their library database works is by linking a book number to a file's md5 sum. On the filesystem they are stored something like `$drive:\$batch\$sum` where `$drive` is a Windows drive letter, `$batch` is the primary key of the document rounded to the nearest 1k, 1…
I could be wrong but I think technically a PDF exploit only affects a single viewer program, like Acrobat on windows, right?
Here is an example file: https://we.tl/q90gXERGmx
Re: Is Firefox lying to users about viruses in downloads?
#57Earlier quoted context omitted.
And if only developers understood UX. The "lie" the author was complaining about was that Firefox is miscommunicating what it did: It warned that a concrete file was containing malware when it actually found a suspicious domain. Depending on context, that might make a huge difference - e.g., if a user got such a warning for a file they uploaded themselves, they might get the wrong impression that their system is comp…
Understand security, if there is malware in one file on your server you burn down the server and set up new one. If your machine gets infected you format all because it is insecure by definition. You might even need to throw out physical machine... If you get one it downloads ten other and you don't know which one will pass your virus scanner. It is not fun and games anymore, silly nerds having fun are not doing it.…
Re: Is Firefox lying to users about viruses in downloads?
#58Re: Is Firefox lying to users about viruses in downloads?
#59Earlier quoted context omitted.
Understand security, if there is malware in one file on your server you burn down the server and set up new one. If your machine gets infected you format all because it is insecure by definition. You might even need to throw out physical machine... If you get one it downloads ten other and you don't know which one will pass your virus scanner. It is not fun and games anymore, silly nerds having fun are not doing it.…
What you say is true, but how is this relevant to the discussion at hand?
Re: Is Firefox lying to users about viruses in downloads?
#60Who cares? Flagging sites probably provides an overall benefit for people to be careful on sites where viruses have been detected. People pirating books will still download them ‘cause if they are on a know pirate books site they’ve already accepted some risk. People who don’t know what their doing will still get infected.
In other words, in my opinion, don't cry wolf unless there's an actual wolf, or at least something that could reasonably look like one.